The public must receive more than protection from harm
Artificial intelligence is becoming infrastructure through which people work, communicate, create, receive services, and exercise judgment. The institutions operating it acquire practical power over those activities. Regulation must govern that power, establish responsibility for its consequences, and secure a public return from the capacity being built.
A framework concerned only with preventing the worst outcome leaves the distribution of every benefit to private discretion. A framework concerned only with encouraging innovation asks the public to absorb costs it did not choose. Neither is sufficient.
This framework establishes a federal floor of enforceable rights and operational duties; preserves substantial state, tribal, and local authority; requires the largest operators to contribute usable capacity for public benefit; and makes compliance infrastructure a public investment. Smaller laboratories remain accountable. Their ability to meet the standard becomes a funding obligation rather than a reason to remove the standard.
The governing principle is straightforward: the authority to deploy intelligence carries obligations to the people it acts upon and to the public whose institutions absorb its consequences.
1. Regulate the operation and its authority
The regulated unit is the deployed system: model, agents, tools, memory, data access, external connections, and the powers granted to that combination. A model's size or its developer's identity cannot, by itself, determine the obligations attached to its use.
Every commercial or institutional operator must identify a responsible legal person and maintain an accurate account of what its system can access, retain, transmit, change, or decide. Personal experimentation without deployment to others would not require registration. Deploying the same system into other people's lives brings the applicable duties with it.
Classification shall consider sensitivity of material, consequentiality of decisions, reach, persistence, autonomy, ability to spend or transfer resources, and reversibility. Adding a payment tool or access to medical records can change a classification even when the underlying model is unchanged. A coordinated agent network must be evaluated as a combined operation; dividing a workflow among nominally modest agents cannot avoid the obligations created by their collective power.
Three levels establish proportionate requirements:
- Baseline deployment: truthful descriptions, security appropriate to the activity, scoped authority, a complaint route, incident preservation, and usable records of consequential actions.
- Consequential deployment: additional predeployment evaluation, documented limits, meaningful human review, notice to affected people, and a route to contest decisions concerning employment, housing, credit, education, healthcare, public benefits, or comparable material interests.
- Systemic or exceptionally hazardous deployment: independent testing, staged release, continuous operational assessment, recovery arrangements, and financial provision proportionate to foreseeable harm and dependency.
The implementing rules must specify measurable triggers and examples. Private accreditation cannot be the only route to determining a category. Ordinary baseline products must not need government permission before release; the strongest deployment gates attach to demonstrated categories of consequential or systemic risk.
2. Make permission an operational boundary
The right to use a capability does not transfer authority over the person or their work to its provider. This is the legal consequence of Local Authority, External Capability.
A delegation must identify its purpose, permitted resources and actions, recipients, duration, retention conditions, and revocation mechanism. Providers must offer a practical way to inspect and narrow that delegation. Permission to draft is not permission to publish. Permission to analyze private work is not permission to retain it for unrelated evaluation, training, commercial development, or competitive research.
Materially different secondary uses require a separate, intelligible authorization or an independently applicable legal basis. A buried contractual provision cannot silently enlarge the operational grant. Nor may an agent enlarge its own grant because a tool happens to be available.
For consequential operations, the person or institution delegating authority must receive a durable record sufficient to establish what was authorized, what occurred, where material went, and which actor was responsible. That record should be exportable and held independently of the provider's continued cooperation. It must not require collecting complete private conversations into a government database.
Revocation must stop future authorized activity and trigger deletion or restriction where applicable. The interface must distinguish actions that can be reversed from disclosures or completed transactions that cannot. Restrictions on secondary use survive a change of subcontractor, model, account status, or ownership.
The same duties apply when government purchases or operates AI. Public-benefit work does not confer a general exemption from privacy, civil rights, or due process.
Registered maker and verifiable model identity
Every model placed into commercial or institutional use must possess the ability and capacity to identify its registered maker and provide an independently verifiable link to that maker. The registered maker must maintain the corresponding means of authenticating the model as its own. Neither obligation may be replaced by a distributor’s unsupported assertion or a model’s unverified self-description.
The identity response must name the responsible legal entity, the model’s registered identifier and version, and the verification record. It must be available through a standard machine-readable interface and, where the system supports conversation, through an ordinary question about its origin. Systems without conversational interfaces must expose the same information through their operational interface. Identity disclosure is a required function, not an optional behavior that ordinary prompting or product branding may suppress.
Verification must bind the maker’s attestation to the identified model artifact or deployed version. A signed release manifest, artifact fingerprint, and authenticated deployment record can provide that chain; implementing standards may recognize equivalent methods that demonstrate the same binding. A copied certificate or a model repeating a maker’s name is insufficient. Verification must establish both the maker’s registered identity and the connection between that attestation and the model being supplied or operated. A signature establishes what a maker attested to; evidence connecting the running service to that attested version remains a separate requirement.
The registry must retain historical attestations, transfers of responsibility, compromised credentials, and revocation status. Verification must not require sending users’ prompts, private work, or conversation histories to the maker. Public verification material must remain usable if the maker closes, is acquired, or withdraws a product. Withdrawal changes current support or authorization status; it does not erase historical origin.
Fine-tuning, merging, distillation, and other material transformations create a derivative identity record. The responsible modifier must identify itself and retain the documented upstream lineage. The original maker verifies its own contribution; it is not required to endorse changes it did not make. Deployers must identify the models actually used, including routed or substituted models, and preserve the identity associated with each consequential operation. A product name cannot conceal a change in model or responsible entity.
A legacy or recovered model whose origin cannot be established must be explicitly recorded as origin-unverified. Its operator must assume responsibility for bringing it into conformity before covered deployment; operator registration cannot be passed off as proof of original authorship. False attribution, removal of required identity mechanisms, and knowingly supplying a substituted model under another model’s attestation are violations.
Registered identity establishes origin and responsibility. It does not certify safety, confer ownership of training material, or replace the duties attached to the model’s actual use. The implementation standard must test whether identification survives ordinary deployment and modification, whether substitution is detectable, and whether the verification record can be checked independently of the party making the claim.
3. Responsibility must survive the handoff
The framework borrows mature regulatory functions rather than importing an entire industry's bureaucracy. Agricultural grading illustrates common classification; livestock traceability illustrates continuity across custody changes; controlled transfers illustrate accountable boundaries; staged medical evaluation illustrates evidence before and after release; accident investigation illustrates shared learning; financial supervision illustrates obligations arising from systemic dependency.
For AI, each material handoff must preserve a system identifier, relevant version, permitted purpose, known limitations, evaluation provenance, and the actor accepting responsibility for the next operation. This record need not expose proprietary weights or private source content to the public.
Developers answer for representations and defects within their control. Integrators answer for the capabilities and access they combine. Deployers answer for the context, authority, and consequences of use. Infrastructure providers answer for duties attached to infrastructure they control. Liability follows conduct, knowledge, control, and preventability; an injured person must not have to reverse-engineer a supply chain before receiving a response.
A designated lead operator must coordinate incident response for each deployment. This coordination duty does not erase other actors' responsibility. Contract terms may allocate costs among firms but may not extinguish statutory remedies available to affected people.
Serious incidents require timely confidential reporting, evidence preservation, correction, and notice to affected parties where appropriate. Published incident learning must remove identifying and exploit-enabling details. Independent technical investigation should explain how failures occurred, while enforcement authorities determine violations. Reporting a failure does not confer immunity for causing or concealing it.
4. Federal rights, state choices, local authority
The statute establishes this framework as a floor, not a general ceiling. The federal government supplies national rights, interoperable records, minimum evaluation duties, interstate coordination, and systemic oversight. States retain authority to enact stronger protections and determine whether particular deployments belong in their public institutions and regulated services. Tribal governments participate in their own sovereign capacity.
The statute expressly preserves state consumer-protection, civil-rights, privacy, professional-practice, and public-procurement authority except where a specifically identified provision makes compliance with both rules impossible. A general claim that local rules inconvenience a national product is not sufficient. Sector-specific provisions must identify and resolve conflicts expressly rather than defeat this reservation of authority through blanket preemption.
State participation is voluntary and federally supported. The federal government enforces its own baseline where a state does not participate. States do not have to establish new agencies to obtain protections for residents.
The following questions are deliberately reserved for state and local design:
| Area | National guarantee | State, tribal, and local design space |
|---|---|---|
| Public services | Notice, accountable decisions, review, accessible remedies | Which uses are permitted in schools, clinics, benefits offices, courts, and municipal services; stronger limits or prohibitions |
| Public-benefit capacity | An enforceable contribution and fair access | Local priorities, eligible institutions, service delivery, language access, and community governance |
| Intelligence utilities | Portability, security, scoped delegation, nondiscrimination | Cooperative, municipal, nonprofit, or other accountable ownership; local stewardship and procurement |
| Physical infrastructure | National reporting and baseline obligations | Siting, water, energy, emergency readiness, and community-benefit arrangements within applicable authority |
| Implementation | Common evidence format and minimum protections | Additional context-specific tests, inspection priorities, and remedies |
Participating states receive planning funds to convene residents, workers, small laboratories, public agencies, and affected communities—not only major vendors. Within twelve months, each participating jurisdiction publishes a supplement naming its choices, unresolved questions, responsible institutions, and costs. Local governments receive a defined role and a share of planning resources through the participating state; tribal funding is direct.
A common evidence packet can satisfy identical requirements across jurisdictions. Stronger local requirements remain possible, but must identify the additional question they answer rather than demand that an institution reformat the same evidence fifty times.
Locality concerns who can decide as well as where servers stand. A neighborhood utility can purchase national compute while residents retain authority over their records and purposes. Federal support must accommodate that arrangement rather than make remote platform membership the price of participation.
5. A public-benefit compute obligation
The largest AI operators shall contribute a defined portion of usable capacity to an independently administered public-benefit pool. Contribution is an obligation, not a discretionary donation or a marketing valuation.
Covered large operators shall contribute one percent of capacity-equivalent service. The implementing schedule shall specify the covered enterprise threshold, assessment base, and measurement method, supported by a published fiscal and capacity analysis. A consolidated-enterprise rule prevents fragmentation into smaller affiliates.
The accounting system must distinguish training, inference, storage, and secure execution. It should measure delivered service by workload class, supported by metered resources, independent benchmark results, availability, and actual cost. Raw accelerator-hours alone are insufficient. Providers must not satisfy the obligation with unusable off-peak capacity, expiring credits, inflated retail prices, or services that require recipients to buy an expensive proprietary stack.
A monetary alternative is acceptable only where the administrator can procure equivalent usable capacity and operating support. Assessment should occur once at a defined point in the capacity chain, with documented credits preventing duplicate charges on the same service. This obligation is separate from remedies for misconduct and does not purchase permission to violate another provision.
At least half of the initial pool shall be reserved for state, tribal, and local public-benefit projects, subject to review after the first operating year. Allocation should account for unmet need, population, rural access, and institutional capacity—not merely the quality of grant-writing teams. The remainder supports shared national services, independent research, emergency response, and common infrastructure. Small institutions need a short application route and technical assistance.
Eligible uses include online predator prevention and victim support, fraud detection, disability access, public-interest science, and locally selected service needs. Funding must cover secure operations, data preparation, stewardship, and evaluation as well as compute. Hardware without the capacity to use it is not a public benefit.
A publicly appointed allocation board, including state, tribal, local, technical, and community representation, publishes selection criteria, conflicts, awards, service delivery, and outcomes. Contributors may supply expertise but may not control allocation to their own products or extract research, training rights, or commercial access from beneficiaries as a condition of service. Procurement and appeal processes must be independent of contributors.
6. Signal Hunting: Make Protection Pay
Protection needs an economic engine powerful enough to compete for the people, attention, and technical ability that exploitation already attracts. Signal Hunting makes useful protective work financially rewarding. The person or team that produces a verified result earns the return. Skill compounds into reputation, access to harder assignments, and greater earning power.
Compensation follows verified contribution. Public-benefit compute lowers the cost of entering the field; funded challenges create demand; competition identifies ability; performance payments make that ability a livelihood. The system feeds both motives deliberately. People can pursue public protection because it matters and because they want to win, earn, and build something valuable. Public benefit must not depend on everyone working for altruistic wages.
Fund the work before asking people to pursue it
Public agencies, platforms, insurers, and other institutions shall be able to post funded protective challenges through an accountable exchange. Each challenge defines the authorized scope, acceptable methods, evidence standard, reward, independent validator, payment deadline, and appeal procedure before work begins. Rewards are escrowed. A sponsor cannot accept the result and then decide the work was merely volunteer assistance.
Paid outcomes include a reproducible exploit finding within an authorized environment, a validated fraud pattern, a verified connection that materially advances an authorized investigation, or a tested detection method that improves performance against agreed benchmarks. A useful result can earn payment before an arrest, prosecution, or eventual recovery: contributors must not carry the financial risk of decisions and delays they do not control. Where legally available and independently attributable, recovery-based awards can supplement milestone payments.
Reward schedules scale with difficulty, reliability, and operational value. Connected contributions receive a disclosed division of the reward; the final submitter cannot take all the value generated by earlier investigators. Duplicate reports follow published precedence and contribution rules. Independent review resolves contested credit. Validated methods can earn additional revenue through licensing or service contracts on terms disclosed when the challenge is posted.
Make the competition worth watching and worth winning
The league turns demonstrated skill into a public competition. Teams compete on cleared or synthetic challenge material, with scoring that rewards accuracy, speed, calibrated confidence, and reproducibility. Correctly dismissing a misleading pattern earns credit. Fabricated findings, evidence manipulation, and unauthorized access trigger disqualification, repayment, and applicable enforcement.
Prize purses, sponsorship, media revenue, and authorized wagering on competition performance form an integrated commercial layer. Published revenue-sharing terms direct money to competitors, league operations, and further protective work. The business model is designed to reward exceptional performance, not merely reimburse participation.
DraftKings' exchange-connected distribution provides a relevant structural example.[1] Signal Hunting supplies the contest, integrity controls, and independently auditable results. Authorized market intermediaries supply contract distribution, settlement, and the financial-market functions they are licensed to perform. This separates functions without removing the financial incentive that makes the design distinctive.
The market interface belongs in the implementation call from the beginning, alongside the contest and the professional challenge exchange. Its rollout must meet the applicable jurisdiction's requirements. Federal and state authority over sports event contracts remains contested; market access must be established for the actual product rather than inferred from another company's launch.[2]
Pay for protection without making accusation the product
The paid unit is verified work, not a person named, an arrest count, or an allegation made entertaining. Live sensitive cases remain within authorized investigative environments. Spectators and bettors see competition performance, not victims' records. Investigators validate operational leads independently, and people who control challenge answers or settlement cannot wager on those outcomes.
These controls protect the economic model itself. A market that pays for suspicion will manufacture suspicion. A market that pays for independently verified work can make protection a serious source of income. Validation must therefore be independent of both the competitor seeking payment and the sponsor seeking a preferred finding, with decisions recorded and appealable.
Make public capacity productive
The public-benefit pool supplies secure compute, testing environments, and access for qualified entrants who lack capital. Sponsors supply funded demand. Competitors and small laboratories supply skill, methods, and tools. Validated results generate payment and evidence of capability; commercial revenue finances further rounds and expands the work available.
State, tribal, and local institutions define challenges grounded in the harms they face. A rural fraud problem need not win the attention of a national platform before it becomes funded work. Shared national infrastructure lets those institutions purchase capability without surrendering authority over the underlying records or investigations.
Performance reporting shall track participant earnings, payment speed, verified outcomes, false positives, repeatable methods, public costs, and revenue returned to protective work. The test is whether the system makes doing protection well economically attractive and produces protection worth paying for.
7. Smaller laboratories meet the rules and receive support
A small laboratory can deploy a consequential system. A large corporation can operate an ordinary tool. Company size determines assistance and contribution obligations; operational risk determines protections.
The statute creates a refundable compliance credit for eligible independent small operators, paired with advance grants and public testing vouchers. Refundability matters because a pre-revenue laboratory may owe no income tax. Advance support matters because reimbursement after expenditure does not solve a cash shortage.
Eligible expenses include internal engineering, security testing, accessibility, incident systems, evaluation, and independent assessment required by the framework. Support should pay for building reliable operations, not predominantly for purchasing reports. Awards should use published schedules and capped eligible costs, with increased support for the smallest operators and no cliff that makes modest growth unaffordable.
Affiliation, beneficial ownership, and consolidated resources determine eligibility. Large firms cannot place regulated activity in a nominally small subsidiary to obtain the subsidy. Related-party billing, repeated claims for the same work, and inflated consultancy charges are ineligible. Good-faith use of public tooling supports evidence of compliance but is not immunity from liability.
The tax credit, grants, regulator staffing, and compute obligation require an explicit fiscal score and funding legislation. None should be presented as costless. The design objective is to spend public money on reusable capacity and safer operations rather than repeated interpretation of the same requirement.
8. Compliance infrastructure is a public utility
Every binding requirement must be available in plain language and in an open, versioned machine-readable form. Each requirement must identify its legal source, applicable systems, effective date, necessary evidence, responsible actor, and review route. Human-readable law remains controlling; an automated interpretation cannot quietly become a new legal duty.
The government shall maintain a free reference implementation covering classification assistance, delegation records, evaluation scheduling, incident reporting, evidence export, and rule-change notifications. Sensitive operational records remain with the responsible institution except where lawful reporting or inspection requires disclosure. The public service must support local execution and selective disclosure.
Institutions should produce evidence once, maintain it as operations change, and reuse it for equivalent obligations. Products must support open export, migration, independent testing, and replacement. No vendor may make a proprietary certificate the sole means of demonstrating compliance. Rules must be usable without hiring an approved intermediary.
Commercial products remain eligible to compete on usefulness, reliability, and cost. Public contracts should purchase interoperable functions and maintenance, with sufficient public rights to preserve continuity if a supplier fails. The regulator must not depend on one contractor to interpret its own rules. Vendors involved in drafting requirements must disclose conflicts and receive no exclusive implementation advantage.
Annual reporting shall measure actual staff hours and expenditure by institution size, duplicate reporting, concentration among suppliers, time to remediation, and demonstrated protection. If paperwork rises without improving outcomes, the implementing agency must revise the process publicly. Administrative burden is a design failure to correct, not proof that regulation is serious.
9. Enact the framework, then open implementation to the public
The sequence matters. Congress establishes rights, duties, resources, and delegated authority. The government then opens a funded call for submissions on implementation: what works, what is missing, where local circumstances change the answer, and how obligations can be fulfilled economically.
Within ninety days of enactment, the coordinating agency shall open a public docket and accessible submission routes. Small laboratories, municipalities, tribal governments, disability organizations, workers, independent researchers, and affected individuals must be able to participate without commissioning legal briefs. Participation grants should support substantial technical contributions from under-resourced groups.
The agency publishes a response matrix showing what submissions changed, what it rejected, and why. Proposed implementing rules then undergo applicable notice-and-comment procedures before becoming binding. This preserves the requested post-enactment invitation without reducing public participation to commentary after every implementation decision is settled.[3]
A second, separate call solicits compliance products against the published requirements and open interfaces. Award criteria include total institutional cost, interoperability, privacy, accessibility, local operation, and verified performance. Small suppliers receive realistic access through modular awards and paid pilots. Awards must fund maintenance and migration, not just demonstrations.
Pilots inform revisions but cannot authorize violations of underlying rights. A product that passes a technical test has passed that test; it has not received an unrestricted legal blessing. Material rule changes require transparent versioning, transition periods appropriate to risk, and updated public tools.
10. Enforcement and the first implementation cycle
The statute must assign federal coordination, inspection powers, and enforcement responsibility expressly, preserving existing sector regulators' jurisdiction and providing joint-investigation procedures. State attorneys general shall have authority to enforce the federal floor, with coordination to prevent duplicative recovery while preserving remedies.
Available remedies include stopping unauthorized operations, correcting records, restitution, damages where established, and civil penalties proportionate to severity, culpability, and economic benefit. Individuals need a statutory route to relief for specified rights violations, including unauthorized consequential use and unlawful retention. Small size does not excuse deliberate misconduct; financial support makes compliance feasible, not optional.
The first eighteen months should produce the public docket, state design grants, proposed and final initial rules under applicable procedures, a working free compliance service, a costed public-compute allocation pilot, and independently evaluated Signal Hunting trials. Deadlines for binding duties must allow realistic implementation while preserving existing legal protections throughout.
At the first annual review, the public should be able to determine who gained usable capacity, whether local institutions gained decision-making power, whether small operators could meet the rules, whether harm was corrected, and whether compliance costs purchased actual protection. Those are the measures of this framework's success.
The country does not need an industry devoted to explaining why accountable intelligence is too expensive. It needs accountable intelligence that institutions of different sizes can afford to operate—and a public that receives a meaningful share of its capacity.
Sources
- DraftKings launch announcement, December 19, 2025. Supports the exchange-connected product architecture; it does not establish approval of Signal Hunting contracts.
- CFTC prediction-market jurisdiction position and 2026 event-contract rulemaking materials. The agency position is not presented here as resolution of all litigation or state authority.
- National Archives: regulatory process. Notice, public comment, consideration, and final rules inform the implementation sequence.
- NIST AI Risk Management Framework. Existing voluntary risk-management infrastructure can inform evidence formats; this framework establishes enforceable obligations beyond a voluntary framework.
- NSF National Artificial Intelligence Research Resource. A relevant existing shared-resource initiative; the mandatory contribution and locally governed allocation specified here are distinct policy choices, not descriptions of NAIRR.